19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

originator identifier (CSID) is not disguised or, where ISDN is used, if the<br />

originator does not withhold his call number. If it is not possible to determine<br />

the originator's fax number, the only remaining option is to expand the<br />

existing capacity, as described above.<br />

Another potential problem with a fax server is hard disk capacity. <strong>The</strong> danger<br />

that an adversary will deliberately exhaust the hard disk capacity through an<br />

attack is slim. A single faxed DIN A4 page occupies around 70 KB. Given<br />

that most hard disks today hold several gigabytes, when one considers the<br />

telephone charges that would be incurred, an attack of this kind is improbable.<br />

Generally, all incoming and outgoing fax transmissions are stored either<br />

permanently or temporarily on the hard disk of the fax server. What happens<br />

then depends on the faxed server application and possibly on the configuration<br />

as well. One possibility is that all faxed transmissions are permanently stored<br />

or archived on the hard disk of the fax server. When this mode of operation is<br />

employed, depending on the volume of faxes, it is possible for the hard disk<br />

capacity to quickly become exhausted. In this case steps should be taken to<br />

ensure that outgoing fax transmissions and incoming faxes which have already<br />

been read are archived as soon as possible on external data media and deleted<br />

from the fax server. To achieve this result, the amount of memory placed at<br />

the disposal of users on the fax server should be limited. In addition, an SOP<br />

should be issued to the effect that fax transmissions which are no longer<br />

required are to be deleted. This applies especially to unsolicited advertising<br />

material received. Regular checks of the amount of free storage space on the<br />

fax server's hard disk should be performed by the fax mail centre.<br />

Additional controls:<br />

- At what times is the fax server heavily loaded?<br />

- Are there any standard operating procedures in place restricting the<br />

sending of faxes at busy times to urgent cases?<br />

- Is permanent archiving of faxes not performed on the fax server?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Ensure hard disk has<br />

sufficient space

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!